Privacy & security
Your data, handled properly
Reeve is built and run by Kitt Technology Limited, a company certified to ISO/IEC 27001, the international standard for information security management. The platform and its database are hosted in the EU, in Amsterdam, and every connection to Reeve is encrypted. Each organisation sees only its own buildings and work, and a service partner sees only the jobs it has been given. We handle personal data under UK GDPR, we never sell it, and you can ask us at any time what we hold about you or to delete it.
Last updated 5 October 2026

ISO/IEC 27001 certified
Kitt Technology Limited, the company behind Reeve, holds ISO/IEC 27001 certification for how it manages information security, with independent audits.
Hosted in the EU
The application and database run in Amsterdam. Uploaded files are stored in Western Europe.
Separated by organisation
Every record belongs to one organisation. Partners see only the work assigned to them.
UK GDPR, never sold
We process personal data lawfully and only to run the service. We never sell it.
Who we are
Reeve is a trading name of Kitt Technology Limited, registered in England and Wales (company no. 11349572), 44-46 Sekforde Street, EC1R 0HA. This notice covers reeve.fm, the Reeve platform at app.reeve.fm, the Reeve mobile apps, and the building apps we run for our customers' occupants on workplace.reeve.fm.
When a customer, such as a property owner or managing agent, uses Reeve to run its buildings, the customer decides what data goes in and why. For that data the customer is the controller, and we process it on their behalf. For our own records, such as accounts, billing, support, security and marketing, we are the controller.
What we collect
People who use Reeve. Your name, work email address, phone number if you give one, the organisation you belong to and your role in it, and a profile photo if you add one. Sign-in is passwordless: we email you a one-time code or link.
Work records. Service requests, work orders, jobs, quotes, comments, messages, photos, documents and form answers that you or your colleagues add, including the names of the people involved.
Operatives using the Reeve Operative app. Your device location at the moment you check in to or out of a job, to confirm you attended the right site. The app does not track your location continuously or in the background. Your camera and photo library, only when you choose to add a photo. A push notification token, if you allow notifications.
Messages. If your organisation connects WhatsApp, email or Slack to Reeve, the messages sent through that channel, with the sender’s name and number or address.
Technical data. IP address, browser and device type, app version, error reports and product usage events. We use these to keep the service running, find faults and improve the product.
Website visitors. Details you give us through the enquiry form or chat on reeve.fm, such as your name, contact details and the address of the property.
How we use it, and our legal basis
Running the service. We sign you in, route and schedule work, record what was done, and notify the people involved. Our legal basis is the contract with you or your organisation.
Security and reliability. We monitor for errors and misuse, fix faults and improve the product. Our legal basis is our legitimate interest in running a secure, reliable service.
Records the law requires. We keep financial and safety records. Our legal basis is legal obligation.
Location at check-in and check-out. We record it because we, your employer and the customer have a legitimate interest in confirming that work happened at the right site. Your device asks your permission before the app can use location, the camera, your photo library or notifications, and you can change that in your device settings at any time.
Analytics and session recording. Only if you accept them in the app. Our legal basis is your consent, which you can withdraw at any time. Before you choose, we only collect anonymous statistics, as described under Cookies and storage.
You do not have to give us personal data, but we need your name and email address to create your account, and the Operative app needs your location to check you in to a job. We do not make decisions about you based solely on automated processing that have legal or similarly significant effects.
How Reeve uses AI
Some Reeve features use large language models, including the Reeve assistant and the enquiry chat on reeve.fm. When you use one, the text that task needs is sent to a model provider through OpenRouter, our model routing service. The providers we use are Anthropic, OpenAI, Google and xAI, and they are listed with our other subprocessors below.
Where your data is
The Reeve application and database run on Railway in Amsterdam, the Netherlands. Uploaded files are stored with Cloudflare in Western Europe. Error monitoring and product analytics run in the EU.
Some subprocessors, such as email delivery and AI model providers, process data in the United States. Those transfers are covered by the safeguards in each provider’s data processing terms: the UK International Data Transfer Addendum, or the UK Extension to the EU-US Data Privacy Framework.
How long we keep it
We keep personal data while your account, or your organisation’s contract with us, is active. Records tied to completed jobs and work orders, and our audit logs, are kept where legal, regulatory, tax or contractual reasons require it, typically for up to 7 years, with personal identifiers removed or pseudonymised where possible.
When a customer’s contract ends, the customer can ask us to return or delete its data.
How we protect it
Kitt Technology Limited is certified to ISO/IEC 27001. Our hosting provider, Railway, is SOC 2 Type II certified.
Every connection to Reeve uses HTTPS. Sign-in is passwordless, so there are no Reeve passwords to steal or reuse. Every record belongs to an organisation, and each request is checked against the organisation you are acting for before any data is returned. Access to production data inside Reeve is limited to the people who need it to run the service.
If we become aware of a breach that affects your data, we will tell affected customers without undue delay, and the Information Commissioner’s Office where the law requires it.
Your rights
Under UK GDPR you can ask for a copy of your personal data, ask us to correct or delete it, object to or restrict how we use it, and ask for it in a portable format. Email privacy@reeve.fm.
If your data is in Reeve because a customer or service partner uses it, we may pass your request to them, because they decide how it is used. To delete your own Reeve account, see Delete your Reeve account.
You can also complain to the Information Commissioner’s Office at ico.org.uk.
For customers assessing Reeve
We can provide our data processing agreement, a copy of our ISO/IEC 27001 certificate, and answers to your security questionnaire. Email privacy@reeve.fm.
Changes to this notice
We update this notice when what we collect, or who we share it with, changes. The date at the top shows when it last changed.
Contact
Questions about this notice or your data: email privacy@reeve.fm, or write to Kitt Technology Limited, 44-46 Sekforde Street, EC1R 0HA.
This notice is also published at reeve.fm/privacy, with the cookies the website sets.